PDA Best Practices
PDA mistakes become full custody failures. Apply this list when designing seeds, storing bumps, and signing CPIs.
Search across all documentation pages
PDA mistakes become full custody failures. Apply this list when designing seeds, storing bumps, and signing CPIs.
SEEDS.md.invoke_signed call in PRs.invoke_signed inside validated instruction handlers. No public signing endpoints.Still review custom seeds and CPI signers.
As needed - rent cost trade-off.
Emit events with PDA type prefix.
Payer funds at create.
Transfer lamports out; zero data.
Different addresses - intentional.
Infeasible - bump search only.
Signs payer not PDA.
Supported in 0.6.x.
OK - security from seeds not secrecy.
Recommended.
Include PDA signing paths.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 19, 2026